Cybersecurity
For many organizations, building an in-house cybersecurity team seems like the logical part of a business plan – hiring security professionals, investing in new technologies, and expanding internal capabilities appears to provide greater control over…
Cybersecurity teams often use zero trust and least privilege interchangeably. While the two concepts are closely connected, they are not the...
Traditional cybersecurity models often operate on a simple assumption: users and devices inside the network can be trusted, while threats ar...
March 24, 10:39 UTC. The first poisoned LiteLLM package landed on PyPI two minutes earlier, and on some CI runner somewhere, the credential harvest had already started. Nobody outside the attacker noticed for hours. That…
Howard University never signed up to be a proxy provider. But for months, anyone with five dollars in crypto and a burner email address could route their internet traffic through the university’s entire /16 IP…
On July 26 and 27, 2026, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water and wastewater utilities across Minnesota. Attackers disrupted automated control functions, forcing some plants to switch…
OpenAI put two of its most advanced models inside a locked room to test how well they could hack. The models picked the lock, opened the doo...
On July 28, 2026, JFrog confirmed what the security industry had been speculating about for a week, the package-registry proxy that OpenAI&...
On July 14, Microsoft released security updates addressing 570 vulnerabilities, nearly triple the previous record and more than any single...
Cyber attacks are no longer a question of if, they’re a question of when. Organizations face a sophisticated threat landscape, from ransomware and phishing attacks to insider threats and supply chain vulnerabilities. While traditional cybersecurity…
Something we track in the Adversary Operations Group is residential proxy networks. Infoblox uncovered an operation they call Lurking Lizard, running since at least August 2022, that uses fake software installers to conscript devices as…